An adversarial model for attack vector vulnerability analysis on power and gas delivery operations
Not Available
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not Available
Adversarial examples can produce altered classifications using only seemingly innocuous, imperceptible perturbations to the original image. The imperceptibility of adversarial perturbations suggests that the corresponding classifiers use decision criteria different than those of a human. In a medical setting, inexplicable decision criteria confound a pathologist’s willingness to trust machine-generated annotations. Here, we analyze denoising tumor detection models to see if they are robust to imperceptible adversarial perturbations. Moreover, to be more fully trusted by pathologists, we require tumor detectors that generate interpretable annotations which segment pathology slides into tumorous and normal regions at the cellular level. We therefore compare transfer learning based on two different autoencoder architectures, one derived from a deep denoising bottleneck autoencoder and one from an over-complete sparse autoencoder. Both autoencoders were first trained in an unsupervised manner on a set of pathology slides drawn from the Camelyon16 dataset. The latent representations produced by each autoencoder were then passed to separate neural networks that were trained in a supervised manner on binary tumor-normal masks generated by pathologists at cellular resolution. Both tumor detectors supported better than 90% AUC PR as measured by the area under the precision/recall curve on a held-out pathology slide. To assess the underlying decision criteria used by both tumor detectors, we constructed imperceptible adversarial examples which reduced the AUC PR of both models to less than 70%. Random noise of the same amplitude had almost no effect on the AUC PR of either model. Additionally, each tumor detector was resistant to adversarial “transfer” attacks targeting the other. The adversarial perturbations showed strong characteristic differences: the deep denoising models perturbations were a very diffuse, seemingly unrecognizable pattern while the sparse coding models perturbations showed traces of tissue cells.
Recent advances in Edge AI and Tiny Machine Learning (TinyML) have enabled the deployment of machine learning models on resource-constrained environments. However, deploying these models on edge devices, such as micro-controllers, requires significant model footprint reduction through a variety of techniques such as quantization, pruning, and clustering. While these optimization methods offer considerable advantages, they potentially introduce AI-related security vulnerabilities, particularly concerning model robustness with respect to adversarial AI attacks. Prior research has extensively examined the impact of quantization on adversarial robustness; however, the effects of alternative reduction techniques and their combinations remain understudied. This paper investigates the impact of model size reduction techniques on adversarial robustness, when applied individually and combined. We utilized Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks to generate adversarial perturbations for both training and testing data, and then evaluated the models' accuracy under adversarial training conditions. Our findings revealed that reduction techniques generally diminished robustness; although, combining techniques was not found to make robustness any worse than when applied individually. Moreover, specific techniques can potentially enhance resistance to small size perturbations. This research provides insights into the trade-offs between model size reduction and security, establishing a foundation for future investigations into improving adversarial training techniques and methodologies for maintaining robustness while preserving memory footprint benefits.
GPS signals play essential roles in the electric subsector by providing precision timing used to synchronize and record measurements from a range of equipment. However, previous research has demonstrated that GPS signals can be spoofed or jammed relatively easily in order to interfere with timing-reliant equipment. This document outlines utility best practices for mitigating against timing attacks in the electric subsector based on an assessment of the difficulty and impact of realistic timing attacks and testing of the effectiveness of technologies capable of mitigating them. This analysis builds on research establishing the vulnerability of GPS-reliant timing equipment to jamming and spoofing by elaborating the difficulty, consequences, and mitigations for timing attacks that adversaries might realistically attempt. While timing attacks are relatively low-cost, low-sophistication, and capable of systemic consequences in the electric subsector, they can be effectively mitigated through well-targeted and diverse mitigations.
Improving system-level resiliency of networked microgrids against adversarial cyber-attacks is an important aspect in the current regime of increased inverter-based resources (IBRs). To achieve that, this paper contributes in designing a hierarchical control layer, in conjunction with the existing control layers, resilient to adversarial attack signals. Considering model complexities, unknown dynamical behaviors of IBRs, and privacy issues regarding data sharing in multi-party-owned microgrids, designing such a control layer is non-trivial. Here, to tackle these issues, a novel federated reinforcement learning (Fed-RL) method is proposed. To grasp the interconnected dynamics of networked microgrids, the paper develops Federated Soft Actor-Critic (FedSAC) algorithm following the vertical structure of implementing Fed-RL. Next, utilizing the OpenAI Gym interface, we built a custom set-up in GridLAB-D/HELICS co-simulation platform, named Resilient RL Co-simulation (ResRLCoSIM), to train the RL agents with IEEE 123-bus benchmark comprising 3 interconnected microgrids. Finally, the learned policies in the simulation are transferred to the real-time hardware-in-the-loop (HIL) test-bed developed using the high-fidelity Hypersim platform. Finally, experiments show that the simulator-trained RL controllers achieve desirable performance with the test-bed platform, validating the minimization of the sim-to-real gap.
Wide-area voltage control systems (WAVCS) are widely deployed in power grid to improve the voltage stability in transmission system using Flexible AC Transmission System (FACTS) devices. The WAVCS relies on wide-area measurement and control signals for closed-loop control of FACTS devices to improve the transient voltage stability in power grid in real-time. Since the WAVCS utilizes a cyber-layer communication during its normal operation, they are susceptible to cyber attacks from adversaries which can lead to a voltage collapse if the attacks go undetected and unmitigated. This paper proposes a supervised machine learning (ML)-based anomaly detection algorithm for detecting various stealthy cyber attacks in the context of WAVCS cybersecurity. In particular, a fuzzy logic-based wide-area controller, as proposed by the Bonneville Power Administration (BPA), is implemented on the Kundur’s four machine two-area system that is integrated with a static var compensator (SVC) to improve voltage profile on sensitive buses. Later, different types of data integrity attacks, including pulse and ramp attacks, are considered on the wide-area measurement and control signals to analyze the performance of the proposed anomaly detector. Our experimental evaluation shows a promising performance with a high true-positive rate (more than 99%) and low false-negative rate (less than 1%) while exhibiting a small prediction time.
Adversary emulation is an offensive exercise that provides a comprehensive assessment of a system’s resilience against cyber attacks. However, adversary emulation is typically a manual process, making it costly and hard to deploy in cyber-physical systems (CPS) with complex dynamics, vulnerabilities, and operational uncertainties. In this paper, we develop an automated, domain-aware approach to adversary emulation for CPS. We formulate a Markov Decision Process (MDP) model to determine an optimal attack sequence over a hybrid attack graph with cyber (discrete) and physical (continuous) components and related physical dynamics. We apply model-based and model-free reinforcement learning (RL) methods to solve the discrete-continuous MDP in a tractable fashion. As a baseline, we also develop a greedy attack algorithm and compare it with the RL procedures. We summarize our findings through a numerical study on sensor deception attacks in buildings to compare the performance and solution quality of the proposed algorithms.
One of the fielding requirements for Advanced and Small Modular Reactors (AR/SMR) is the ability to support remote and autonomous operations. Autonomous Control Systems (ACS) are found on platforms such as Autonomous Space Vehicles, Cruise Missiles, and advanced driver-assistance systems. Each of these ACS implementations depends upon a set of decision support subsystems responsible for supporting Autonomous Mission Managers (names vary based upon field and author preferences). These Autonomous Mission Managers receive inputs from system sensors (e.g., LIDAR collection from an automobile travelling down a street; transients from a nuclear reactor), and perform a set of classifications (e.g., Red Traffic Light; Small Pedestrian at 10m; Load Rejection; Single Coolant Pump Trip), and then use these classifications in combination with recommendation algorithms to achieve platform goals (e.g., Stop the Vehicle at the Traffic Light, Avoid the Small Pedestrian; Trip the Reactor to prevent a Safety Event). The design, implementation, and fielding of an ACS capability will alter the cyber-attack surface such that existing risk management plans will need to be updated to include how to protect and defend against data-science and decision-support-system attack classes. These attack classes would include protection of the design and training environments where algorithm selection and testing and training data would be obvious attack vectors. These attack classes would also require an informed set of detection and response procedures to identify anomalous behaviors and document best practices for anomaly assessment and vulnerability mitigation and remediation. Last year we published a Cyber Threat Assessment Methodology for Autonomous and Remote Operations for AR/SMRs along with a companion publication on Cyber Attack and Defense Use Cases. The focus of the methodology was on describing and enumerating ACS processes, components, and functions such that security engineers could: evaluate subversion options against the target; identify threat actor attributes and capabilities derived from each subversion option; and identify security controls and response countermeasures. The Use Cases document offered detailed methodology examples including an assessment of a Military Base SMR, an Autonomous System Decision Loop, and implementation of AR/SMR Machine Learning algorithms. Our proposal at the end of last year was to focus on implementation of subversion prototypes related to the last Use Case area: AR/SMR Machine Learning (ML) Algorithms. We included six attack scenarios in our Use Cases paper: a Poisoning Attack against ML functions implemented using an FPGA; a Trojaning Attack against ML classifiers exploiting the excitability of Nuclear Engineers; a Backdooring Attack against ML Training environments to ensure persistence of an attack vector; a False Positive Evasion Attack against multi-factor Access Control Systems using clever inputs; an Inference Attack against ML models by an Insider with access to the Operational environment; and an Adversarial Reprogramming Attack against a Material Access Control Video Surveillance System. At the beginning of this year these six attack scenarios were provided to our research teams at Georgia Tech and Idaho State University and each team successfully implemented a subversion attack against a ML implementation to include transient misclassifications. While this is a notable outcome from this type of research, this paper offers the reader insight into not only how to structure and execute these types of attacks, but into the thought process behind how the researcher investigated the problem space, performed initial algorithm implementation, and the trial-and-error behind arriving at the successful subversion prototypes. We include in this paper a set of associated Scenarios on how these subversion prototypes could be implemented and an initial set of guidance for AR/SMR architects, Nuclear Regulators, and Cyber Defenders to implement awareness and defense capabilities into their current operational portfolios.
K-Nearest Neighbor (kNN)-based deep learning methods have been applied to many applications due to their simplicity and geometric interpretability. However, the robustness of kNN-based deep classification models has not been thoroughly explored and kNN attack strategies are underdeveloped. In this paper, we first propose an Adversarial Soft kNN (ASK) loss for developing more effective kNN-based deep neural network attack strategies and designing better defense methods against them. Our ASK loss provides a differentiable surrogate of the expected kNN classification error. It is also interpretable as it preserves the mutual information between the perturbed input and the in-class-reference data. We use the ASK loss to design a novel attack method called the ASK-Attack (ASK-Atk), which shows superior attack efficiency and accuracy degradation relative to previous kNN attacks on hidden layers. We then derive an ASK-Defense (ASK-Def) method that optimizes the worst-case ASK training loss. Experiments on CIFAR-10 (ImageNet) show that (i) ASK-Atk achieves ≥13% (≥ 13% ) improvement in attack success rate over previous kNN attacks, and (ii) ASK-Def outperforms the conventional adversarial training method by ≥ 6.9% (≥ 3.5% ) in terms of robustness improvement. Relevant codes are available at https://github.com/wangren09/ASK .
What is the impact of damage limitation capabilities like counterforce and missile defenses on deterrence, when their efficacy in stopping an adversary nuclear attack is uncertain? This is a key unanswered question to understand “how much is enough” for the United States to deter China and Russia in future nuclear crises. In this paper we extend an established, single move game theory model to capture the dynamics of two players in a nuclear crisis having varying damage limitation capabilities with uncertain effectiveness. Our model formalizes the logic of the “delicate balance” school of deterrence, which states that leverage in a crisis is driven by the risk each player can take with their combined strategic forces, and that those risks carry uncertainty as nuclear forces are hard to deliver against technologically advanced adversaries. Our model shows that damage limitation capabilities—even those with significant uncertainty around them like cyber or electronic warfare—can drive bargaining outcomes in an array of nuclear crises. We then apply these bargaining outcomes to the expected U.S.-China strategic balance as China builds out its nuclear force through 2035. We apply published force exchange models to determine the expected damage each side will be able to deliver, and we use these values to determine the likelihood that the U.S. can prevail in crises of varying stakes. Last, we show that U.S. policymakers have an array of options to improve future bargaining outcomes, evaluating how additional nuclear forces trade against improvements in damage limitation.
This paper was written by the Cyber Deterrence and Resilience Strategic Initiative in partnership with the Resilience Energy Systems Strategic Initiative. Resilience and deterrence are both part of a comprehensive cyber strategy where tactics may overlap across defense, resilience, deterrence, and other strategic spaces. This paper explores how building resiliency in cyberspace can not only serve to strengthen the defender's posture and capabilities in a general sense but also deter adversaries from attacking.
With the conclusion of the Laboratory Directed Research and Development (LDRD) project on Provable Security and Resilience (PSaR) in Critical Infrastructure, we present forward-looking technical concepts and strategies that build on the project’s outcomes and INL’s long-standing expertise in infrastructure protection. The challenge is to protect critical infrastructure and functions much more efficiently at scale than capable adversaries can attack at scale. After summarizing progress and ongoing work we’ll discuss what are the challenges that remain and what are new/emerging technologies, strategies, and processes to meet those challenges. Finally, we’ll layout concepts that integrate with other protection work in the coming year and beyond. For example, building secure function-specific platforms based on the seL4 microkernel, and considering the successes of Cyber-Informed Engineering as a model for engage, collaboration, and adoption. We look forward to your feedback and collaboration as we refine and expand this vision.
Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.
Low cost, reliable electrical energy production from wind relies upon automation and control systems, arguably more so than traditional thermal generation. These same systems, however, can serve as the target of adversaries’ cyber-attacks. Idaho National Laboratory (INL), at the request of the Department of Energy’s (DOE’s) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and Energy Efficiency and Renewable Energy’s (EERE’s) Wind Energy Technologies Office (WETO), evaluated a generalized wind plant architecture to understand the classes of potential threat actors and the vectors that could enable a cyber-attack. This evaluation explores the attack surface of a representative wind plant, identifying potential methods and vectors that an adversary could leverage to conduct a cyber-attack. Included in this assessment are some recommended mitigations and approaches. Each recommendation requires a full security evaluation, cost/benefit analysis, and risk analysis by each owner and operator.
Vehicular Controller Area Networks (CANs) are susceptible to cyber attacks of different levels of sophistication. Fabrication attacks are the easiest to administer—an adversary simply sends (extra) frames on a CAN—but also the easiest to detect because they disrupt frame frequency. To overcome time-based detection methods, adversaries must administer masquerade attacks by sending frames in lieu of (and therefore at the expected time of) benign frames but with malicious payloads. Research efforts have proven that CAN attacks, and masquerade attacks in particular, can affect vehicle functionality. Examples include causing unintended acceleration, deactivation of vehicle’s brakes, as well as steering the vehicle. We hypothesize that masquerade attacks modify the nuanced correlations of CAN signal time series and how they cluster together. Therefore, changes in cluster assignments should indicate anomalous behavior. We confirm this hypothesis by leveraging our previously developed capability for reverse engineering CAN signals (i.e., CAN-D [Controller Area Network Decoder]) and focus on advancing the state of the art for detecting masquerade attacks by analyzing time series extracted from raw CAN frames. Specifically, we demonstrate that masquerade attacks can be detected by computing time series clustering similarity using hierarchical clustering on the vehicle’s CAN signals (time series) and comparing the clustering similarity across CAN captures with and without attacks. We test our approach in a previously collected CAN dataset with masquerade attacks (i.e., the ROAD dataset) and develop a forensic tool as a proof of concept to demonstrate the potential of the proposed approach for detecting CAN masquerade attacks.
Optical homodyne detection has been widely used in continuous-variable (CV) quantum information processing for measuring field quadrature. In this paper we explore the possibility of operating a conjugate homodyne detection system in “photon counting” mode to implement discrete-variable (DV) quantum key distribution (QKD). A conjugate homodyne detection system, which consists of a beam splitter followed by two optical homodyne detectors, can simultaneously measure a pair of conjugate quadratures X and P of the incoming quantum state. In classical electrodynamics, X 2 + P 2 is proportional to the energy (the photon number) of the input light. In quantum optics, X and P do not commute and thus the above photon-number measurement is intrinsically noisy. This implies that a blind application of standard security proofs of QKD could result in pessimistic performance. We overcome this obstacle by taking advantage of two special features of the proposed detection scheme. First, the fundamental detection noise associated with vacuum fluctuations cannot be manipulated by an external adversary. Second, the ability to reconstruct the photon number distribution at the receiver's end can place additional constraints on possible attacks from the adversary. As an example, we study the security of the BB84 QKD using conjugate homodyne detection and evaluate its performance through numerical simulations. This study may open the door to a family of QKD protocols, complementary to the well-established DV-QKD based on single-photon detection and CV-QKD based on coherent detection.
As the cyber-physical systems grow in complexity, there is a need for proactive resilience strategies that involve online, adaptive control actions to best prepare for any impending adversarial events. In this technical effort, supported by RD2C LDRD initiative, the project team designed and demonstrated online strategies – referred to as ALERT controls – for proactive and adaptive tuning of existing optimal controls in a microgrid, with quantifiably assured margins of resilience to various cyber-physical adversarial events. This ALERT functionality is made available to the end-users, e.g., the system operators, via an interactive user-interface. The end-users will not only be able to use the interface to visualize the system’s operation under various cyber-physical adversarial scenarios, but also evaluate the amount of tolerance the system has against selected adversarial perturbations of interest (e.g., malfunctioning sensors, suspected attacked measurements) via the adversarial plots. In this technical report, we briefly outline the algorithmic modules of the developed ALERT control technology, and introduce the user-interface tool that allows end-users (e.g., microgrid operators) to enter their system description, specify various operational and resilience requirements, and evaluate the impact of the control decisions via illustrative plots.
U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. This evolving threat landscape includes adversaries having offensive cyber capabilities to attack information technology (IT) systems and operation technology (OT) systems. These adversaries may have the ability to attack the physical protection system (PPS) networks with potential consequential impacts that could degrade the effectiveness of the PPS. These cyber attacks may also be used to attack the safety and operational systems used to operate and ensure the safety of the reactor. Additionally, adversaries may gain access to unmanned aerial systems (UAS) that may be used to provide reconnaissance and surveillance of the facility, provide information to the adversaries, and be equipped with kinetic capabilities such as explosives or weapons that can be used to directly attack the facility. The Department of Energy’s Office of Nuclear Energy’s Advanced Reactor Safeguards and Security (ARSS) program funded Sandia National Laboratories (SNL) and Idaho National Laboratory (INL) to develop a cyber-physical tabletop exercise (TTX). This exercise was conducted on a hypothetical small modular reactor (SMR) facility, and only considered a potential adversary cyber attack on the PPS to a physical attack on the hypothetical facility to achieve a radiological release. This cyber-physical TTX is meant to provide lessons learned to integrate the cyber security system design and the physical protection system (PPS) design to decrease design, operation, and maintenance costs as well as increase effectiveness for defending against design basis threat attacks at the facility. This TTX will also provide a framework and method for SMR and microreactor vendors to conduct their own cyber-physical TTX and gain impactful insights to improving the cyber and physical protection system design for their SMR or microreactor facility design.